PT-2020-6060 · Npm+7 · Y18N+7

Po6Ix

·

Published

2020-11-17

·

Updated

2026-05-18

·

CVE-2020-7774

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions y18n versions prior to 3.2.2 y18n versions prior to 4.0.1 y18n versions prior to 5.0.5
Description The issue is related to Prototype Pollution, which can be exploited by a remote attacker to perform a "prototype pollution" attack. This occurs due to uncontrolled modification of object prototype attributes. The estimated number of potentially affected devices worldwide is not specified. There is a proof of concept (POC) that demonstrates the vulnerability by setting the locale to proto and updating the locale with a polluted object, resulting in the pollution of the prototype.
Recommendations Upgrade to version 3.2.2 or later for versions prior to 3.2.2 Upgrade to version 4.0.1 or later for versions prior to 4.0.1 Upgrade to version 5.0.5 or later for versions prior to 5.0.5 As a temporary workaround, consider restricting the use of the setLocale() and updateLocale() functions until a patch is available. Avoid using the proto locale to minimize the risk of exploitation.

Exploit

Fix

Prototype Pollution

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020:5499
ALSA-2021:0548
ALSA-2021:0551
ALT-PU-2021-2408
ALT-PU-2022-3069
BDU:2021-02865
CESA-2020_5499
CESA-2021_0548
CESA-2021_0551
CLEANSTART-2026-BD71263
CLEANSTART-2026-IS74202
CLEANSTART-2026-JR35772
CLEANSTART-2026-JY06700
CLEANSTART-2026-KN34553
CLEANSTART-2026-KZ45320
CLEANSTART-2026-LJ44720
CLEANSTART-2026-LN12820
CLEANSTART-2026-TX00223
CLEANSTART-2026-WI75198
CVE-2020-7774
GHSA-C4W7-XM78-47VH
MGASA-2021-0372
OESA-2022-1769
OPENSUSE-SU-2021:1059-1
OPENSUSE-SU-2021:1060-1
OPENSUSE-SU-2021:1061-1
OPENSUSE-SU-2021:1113-1
OPENSUSE-SU-2021:2327-1
OPENSUSE-SU-2021:2353-1
OPENSUSE-SU-2021:2354-1
OPENSUSE-SU-2021:2618-1
OPENSUSE-SU-2021_1059-1
OPENSUSE-SU-2021_1060-1
OPENSUSE-SU-2021_1061-1
OPENSUSE-SU-2021_1113-1
OPENSUSE-SU-2021_2327-1
OPENSUSE-SU-2021_2353-1
OPENSUSE-SU-2021_2354-1
OPENSUSE-SU-2021_2618-1
OPENSUSE-SU-2024:11096-1
RHSA-2020:5305
RHSA-2020:5499
RHSA-2020_5499
RHSA-2021:0421
RHSA-2021:0521
RHSA-2021:0548
RHSA-2021:0551
RHSA-2021_0548
RHSA-2021_0551
RLSA-2020:5499
RLSA-2021:0548
RLSA-2021:0551
SNYK-JAVA-ORGWEBJARSNPM-1038306
SNYK-JS-Y18N-1021887
SUSE-SU-2021:2319-1
SUSE-SU-2021:2323-1
SUSE-SU-2021:2326-1
SUSE-SU-2021:2327-1
SUSE-SU-2021:2353-1
SUSE-SU-2021:2354-1
SUSE-SU-2021:2618-1
SUSE-SU-2021:2620-1
SUSE-SU-2021_2319-1
SUSE-SU-2021_2354-1
SUSE-SU-2021_2618-1
SUSE-SU-2021_2620-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Red Hat
Rocky Linux
Suse
Y18N